GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
73
GitHub Actions
53
Go
4,029
Maven
5,000+
npm
5,000+
NuGet
976
pip
5,000+
Pub
13
RubyGems
1,070
Rust
1,404
Swift
61
Unreviewed advisories
All unreviewed
5,000+
422 advisories
Filter by severity
Mercurius's queryDepth limit bypassed for WebSocket subscriptions
Low
CVE-2026-30241
was published
for
mercurius
(npm)
Mar 6, 2026
defuddle vulnerable to XSS via unescaped string interpolation in _findContentBySchemaText image tag
Low
CVE-2026-30830
was published
for
defuddle
(npm)
Mar 6, 2026
@backstage/plugin-scaffolder-backend Vulnerable to Potential Session Token Exfiltration via Log Redaction Bypass
Low
CVE-2026-29184
was published
for
@backstage/plugin-scaffolder-backend
(npm)
Mar 5, 2026
Backstage vulnerable to potential reading of SCM URLs using built in token
Low
CVE-2026-29185
was published
for
@backstage/integration
(npm)
Mar 5, 2026
OpenClaw has cross-account DM pairing authorization bypass via unscoped pairing store access
Low
CVE-2026-32067
was published
for
openclaw
(npm)
Mar 4, 2026
Dark Reader gives users the ability to request style sheets from local web servers
Low
CVE-2025-68467
was published
for
darkreader
(npm)
Mar 4, 2026
OpenClaw's tools.exec.safeBins generic fallback allowed interpreter-style inline payload execution in allowlist mode
Low
GHSA-8mf7-vv8w-hjr2
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw reuses the gateway auth token in the owner ID prompt hashing fallback
Low
CVE-2026-32897
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw's voice-call Twilio replay dedupe now bound to authenticated webhook identity
Low
GHSA-gcj7-r3hg-m7w6
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw: Microsoft Teams media fetch paths bypass shared SSRF guard model
Low
GHSA-7qf6-h84j-8fq4
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw's runtime /debug override path accepted prototype-reserved keys
Low
CVE-2026-27524
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw Vulnerable to HTML injection via unvalidated image MIME type in data-URL interpolation
Low
CVE-2026-32040
was published
for
openclaw
(npm)
Mar 3, 2026
@tootallnate/once vulnerable to Incorrect Control Flow Scoping
Low
CVE-2026-3449
was published
for
@tootallnate/once
(npm)
Mar 3, 2026
mailparser vulnerable to Cross-site Scripting
Low
CVE-2026-3455
was published
for
mailparser
(npm)
Mar 3, 2026
OpenClaw Node system.run approval context-binding weakness in approval-enabled host=node flows
Low
CVE-2026-32058
was published
for
openclaw
(npm)
Mar 2, 2026
OpenClaw's Control UI Static File Handler Follows Symlinks and Allows Out-of-Root File Read
Low
CVE-2026-32020
was published
for
openclaw
(npm)
Mar 2, 2026
OpenClaw macOS companion app (beta): allowlist parsing mismatch for system.run shell chains
Low
CVE-2026-31993
was published
for
openclaw
(npm)
Mar 2, 2026
OpenClaw has Signal group allowlist authorization bypass via DM pairing-store leakage
Low
CVE-2026-31991
was published
for
openclaw
(npm)
Mar 2, 2026
NocoDB has Plaintext Storage of Shared View Passwords
Low
CVE-2026-28360
was published
for
nocodb
(npm)
Mar 2, 2026
NocoDB Vulnerable to User Enumeration via Password Reset Endpoint
Low
CVE-2026-28358
was published
for
nocodb
(npm)
Mar 2, 2026
SvelteKit has deserialization expansion in unvalidated `form` remote function leading to Denial of Service (experimental only)
Low
GHSA-fpg4-jhqr-589c
was published
for
@sveltejs/kit
(npm)
Feb 28, 2026
fast-xml-parser has stack overflow in XMLBuilder with preserveOrder
Low
CVE-2026-27942
was published
for
fast-xml-parser
(npm)
Feb 26, 2026
ENS DNSSEC Oracle Vulnerable to RSA Signature Forgery via Missing PKCS#1 v1.5 Padding Validation
Low
CVE-2026-22866
was published
for
@ensdomains/ens-contracts
(npm)
Feb 25, 2026
OpenClaw Discord moderation authorization used untrusted sender identity in tool-driven flows
Low
CVE-2026-27484
was published
for
openclaw
(npm)
Feb 20, 2026
OpenClaw safeBins stdin-only bypass via sort output and recursive grep flags
Low
CVE-2026-31996
was published
for
openclaw
(npm)
Feb 19, 2026
ProTip!
Advisories are also available from the
GraphQL API